← Vulnerability feed

Vulnerability record · CVE-2014-100005 · published 13 January 2015

CVE-2014-100005: D-Link DIR-600 router CSRF enables admin account creation and remote management

Dlink · Dir 600 Firmware

The D-Link DIR-600 (rev. Bx) with firmware before 2.17b02 is affected by multiple cross-site request forgery flaws in hedwig.cgi, pigwidgeon.cgi and diagnostic.php. An attacker who can lure an authenticated administrator into a crafted request can create an admin account, enable remote management, activate configuration settings or trigger a ping. The flaw matters because it gives an unauthenticated outsider a path to full administrative control of the router through the victim's browser session.

8.0 CVSS 3.1 High CISA KEV since 16 May 2024 EPSS 43% · top 1.3% CWE-352 · Cross-site request forgery
8.0CVSS 3.1 base score, v2 6.8
43%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
9References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev. Bx) with firmware before 2.17b02 allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator account or (2) enable remote management via a crafted configuration module to hedwig.cgi, (3) activate new configuration settings via a SETCFG,SAVE,ACTIVATE action to pigwidgeon.cgi, or (4) send a ping via a ping action to diagnostic.php.

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityThe device is end-of-life with no supported fix, the flaw is in CISA KEV, and EPSS is near the top percentile, though exploitation requires an authenticated admin session to be hijacked.

What it is

The D-Link DIR-600 (rev. Bx) with firmware before 2.17b02 is affected by multiple cross-site request forgery flaws in hedwig.cgi, pigwidgeon.cgi and diagnostic.php. An attacker who can lure an authenticated administrator into a crafted request can create an admin account, enable remote management, activate configuration settings or trigger a ping. The flaw matters because it gives an unauthenticated outsider a path to full administrative control of the router through the victim's browser session.

Impact

An attacker gains the ability to add an administrator account, turn on remote management and change active configuration, effectively taking over the device. That yields full control over routing, DNS and traffic passing through the router.

Attack surface

Reached over the adjacent network through the router's web management interface; the CVSS vector is AV:A/AC:L/PR:L/UI:N, and the description requires the victim administrator's authenticated session to be hijacked. No credentials are needed by the attacker, but the request must be delivered to a logged-in admin, which in practice depends on user interaction despite the UI:N vector.

Exploitation

CVE-2014-100005 is listed in CISA KEV (added 2024-05-16) and has an EPSS 30-day probability of 0.48146 (98.8th percentile), and references include an Exploit-tagged third-party writeup. No ransomware campaign use is documented.

What to do

  • Retire and replace affected DIR-600 rev. Bx hardware, which D-Link and CISA state has reached end-of-life/end-of-service; no supported firmware fix is available.
  • If the device cannot be replaced immediately, disable remote management and restrict administrative access to a trusted management network.
  • Do not browse to untrusted sites or click untrusted links while logged into the router's admin interface, and log out when finished.
  • Apply the vendor advisory SAP10018 guidance where any supported firmware path exists, and verify the running firmware version.
  • Segment or block the router's management interface from general user networks to reduce CSRF reachability.

Detection

  • Monitor router logs for unexpected creation of administrator accounts or changes to remote management settings.
  • Alert on configuration activation (SETCFG,SAVE,ACTIVATE) or diagnostic ping actions originating from unexpected client IPs.
  • Watch for HTTP requests to hedwig.cgi, pigwidgeon.cgi and diagnostic.php with unusual Referer or Origin headers.
  • Audit for new admin logins or management sessions from addresses outside the expected administrative network.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2014-100005 to the Known Exploited Vulnerabilities catalog on 16 May 2024 as "D-Link DIR-600 Router Cross-Site Request Forgery (CSRF) Vulnerability". Required action: This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions. Federal deadline 6 June 2024.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-100005 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2018-25115Dlink dir-110 firmware os command injection vulnerabilityMultiple D-Link DIR-series routers, including DIR-110, DIR-412, DIR-600, DIR-610, DIR-615, DIR-645, and DIR-815 firmware version 1.03, contain a vuln…EPSS 10%10.0CVE-2013-10069Dlink dir-600 firmware os command injection vulnerabilityThe web interface of multiple D-Link routers, including DIR-600 rev B (≤2.14b01) and DIR-300 rev B (≤2.13), contains an unauthenticated OS command in…EPSS 17%9.8CVE-2023-33625Dlink dir-600 firmware command injection vulnerabilityD-Link DIR-600 Hardware Version B5, Firmware Version 2.18 was discovered to contain a command injection vulnerability via the ST parameter in the lxm…EPSS 33%9.8CVE-2023-33626Dlink dir-600 firmware out-of-bounds write vulnerabilityD-Link DIR-600 Hardware Version B5, Firmware Version 2.18 was discovered to contain a stack overflow via the gena.cgi binary.EPSS 1.5%9.8CVE-2013-7471Dlink dir-300 firmware command injection vulnerabilityAn issue was discovered in soap.cgi?service=WANIPConn1 on D-Link DIR-845 before v1.02b03, DIR-600 before v2.17b01, DIR-645 before v1.04b11, DIR-300 r…EPSS 24%9.3CVE-2013-10048Dlink dir-300 firmware os command injection vulnerabilityAn OS command injection vulnerability exists in various legacy D-Link routers—including DIR-300 rev B and DIR-600 (firmware ≤ 2.13 and ≤ 2.14b01, res…EPSS 17%8.9CVE-2025-15194Dlink dir-600 firmware memory buffer overflow vulnerabilityA vulnerability was found in D-Link DIR-600 up to 2.15WWb02. Affected by this vulnerability is an unknown functionality of the file hedwig.cgi of the…EPSS 1.2%5.3CVE-2024-7357Dlink dir-600 firmware os command injection vulnerability** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DIR-600 up to 2.18. It has been rated as critical. This issue affects the functio…EPSS 5.7%

Source: NIST National Vulnerability Database (record CVE-2014-100005), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.